Node.js — программная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 24.21.0 | 24.21.0 | ||
| 24.20.0 | 24.20.0 | ||
| 24.19.0 | 24.19.0 | ||
| 24.18.1 | 24.18.1 | ||
| 24.18.0 | 24.18.0 | ||
| 24.17.0 | 24.17.0 | ||
| 24.16.0 | 24.16.0 | ||
| 24.15.0 | 24.15.0 | ||
| 24.14.1 | 24.14.1 | ||
| 24.14.0 | 24.14.0 |
Показывать по
Количество 1 270
CVE-2015-8860
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.
BDU:2022-01720
Уязвимость программной платформы Node.js, связанная с ошибками управления ресурсом, позволяющая нарушителю вызвать отказ в обслуживании
CVE-2014-7192
Eval injection vulnerability in index.js in the syntax-error package b ...
CVE-2014-7192
Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.
CVE-2014-7192
Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.
CVE-2014-7191
The qs module before 1.0.0 in Node.js does not call the compact functi ...
CVE-2014-7191
The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.
CVE-2014-7191
The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.
CVE-2014-6394
visionmedia send before 0.8.4 for Node.js uses a partial comparison fo ...
CVE-2014-6394
visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2015-8860 The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive. | CVSS2: 4.3 | 5% Низкий | больше 11 лет назад | |
BDU:2022-01720 Уязвимость программной платформы Node.js, связанная с ошибками управления ресурсом, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 4% Низкий | больше 11 лет назад | |
CVE-2014-7192 Eval injection vulnerability in index.js in the syntax-error package b ... | CVSS2: 10 | 13% Средний | почти 12 лет назад | |
CVE-2014-7192 Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file. | CVSS2: 10 | 13% Средний | почти 12 лет назад | |
CVE-2014-7192 Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file. | CVSS2: 10 | 13% Средний | почти 12 лет назад | |
CVE-2014-7191 The qs module before 1.0.0 in Node.js does not call the compact functi ... | CVSS2: 5 | 8% Низкий | почти 12 лет назад | |
CVE-2014-7191 The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array. | CVSS2: 5 | 8% Низкий | почти 12 лет назад | |
CVE-2014-7191 The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array. | CVSS2: 5 | 8% Низкий | почти 12 лет назад | |
CVE-2014-6394 visionmedia send before 0.8.4 for Node.js uses a partial comparison fo ... | CVSS2: 7.5 | 4% Низкий | почти 12 лет назад | |
CVE-2014-6394 visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory. | CVSS2: 7.5 | 4% Низкий | почти 12 лет назад |
Уязвимостей на страницу